Fixed allowed methods for retrieving token with cors

This commit is contained in:
Stian Thorgersen 2013-11-09 13:11:30 +00:00
parent 715109af61
commit 5b19e34f50

View file

@ -435,7 +435,7 @@ public class TokenService {
logger.debug("accessRequest SUCCESS");
AccessTokenResponse res = accessTokenResponse(realm.getPrivateKey(), accessCode.getToken());
return Cors.add(request, Response.ok(res)).allowedOrigins(client).build();
return Cors.add(request, Response.ok(res)).allowedOrigins(client).allowedMethods("POST").build();
}
protected AccessTokenResponse accessTokenResponse(PrivateKey privateKey, SkeletonKeyToken token) {